Privacy Policy
App: sneebly-app (Sneebly App) Last updated: August 25, 2026
Who we are
Sneebly App is the public website and account control plane for Sneebly. It provides marketing and trust pages at https://www.sneebly.app, authenticated signup and sign-in, email and session verification, subscription billing, plan entitlements, and the hosted Account Vault.
This policy describes what we collect and process to run that product today.
What we collect
- Accounts and authentication: When you sign up or sign in, we process your account email and session identity through our authentication provider, Clerk. We store membership links (Clerk user id ↔ tenant) needed to run multi-tenant accounts. We use account email for authentication, security notices, receipts, and operational messages (for example vault continuity reminders).
- Billing and payments: For paid plans we process billing email and payment identity needed for subscriptions. Card payments are handled by Stripe. Sneebly does not store full card numbers on our servers. We may retain Stripe customer identifiers and subscription status needed to enforce entitlements honestly.
- Hosted Account Vault: If you use the hosted Account Vault, Sneebly stores encrypted vault payloads (ciphertext) at rest under your tenant. Item list metadata you choose (such as titles) may be stored for browsing; secret bodies are stored encrypted at rest, never as cleartext password columns.
- Application database records: Account, membership, entitlement, billing-link, and vault ciphertext records needed to operate the control plane.
- Website analytics (optional): When operators enable it, the marketing site may use optional privacy-respecting, cookieless analytics (for example Plausible) to measure aggregate traffic such as pageviews and referrers. We do not send vault plaintext, secret values, emails, or account identifiers as analytics events. If analytics is off, no such script is required to use the product.
- Ordinary web logs: We may receive standard technical information that any web server or hosting platform can see when you visit a public page (for example IP address, browser type, and request timestamps). That information is used to operate and secure the site, not to build advertising profiles.
Honest encryption model
Hosted vault uses server-side envelope encryption with platform-held keys. Authorized API access after authentication and entitlement checks can decrypt for reveal, export, and sync as the product allows. This is not a product where customers alone hold all decryption keys for hosted vault data on the client. Bodies are encrypted at rest; access is authorized per tenant and plan. Support tools show account and vault metadata/counts by default — not vault plaintext.
What we do not do
- We do not sell vault item contents for advertising.
- We do not share one customer’s vault or account data across tenants as a product feature.
- Application logs must not include vault plaintext, secret values, full session tokens, or payment card numbers. Default support tickets are for account metadata only.
- Sneebly App is not a full 1Password replacement. We do not resell metered AI tokens as part of the Sneebly subscription. We do not run customer coding agents on the sneebly.app control plane.
Third-party processors
We use service providers to run the product, including:
- Clerk — authentication and sessions
- Stripe — payments and Customer Portal
- Hosting and CDN for the website and API
- An email provider when transactional mail is enabled
Those providers process data under their agreements with us as needed to deliver the service.
Cookies
We use authentication and session cookies (and similar session storage) required for signed-in account use via Clerk. We do not use advertising cookies or ad pixels on the account site. Optional marketing analytics, when enabled, is cookieless in its basic pageview mode and does not set first-party tracking cookies solely for that mode.
Your browser may still store ordinary technical data associated with loading a website (for example cached assets).
Cancel, continuity, and retention
Canceling Builder (or letting a subscription end) does not immediately hard-delete your hosted vault on day zero. Product continuity defaults are about a 90-day grace period, then about a 30-day readonly/export window, then archive and later hard delete of vault contents per retention policy. Exact dates shown in the product always win over this summary.
Account and billing records may be retained as needed for fraud, tax, and legal obligations. Ordinary web-server or hosting logs are kept only as long as needed for security and reliability, then discarded under the host’s normal log rotation practices.
You can export your vault data during entitled windows (full access, grace, and readonly/export as the product allows).
Your rights
Depending on where you live, you may have rights to:
- Access personal data we hold about you
- Delete personal data we hold about you
- Ask us to correct inaccurate information
- Ask questions about how we process data
To make a privacy request, contact privacy@sneebly.app.
Changes
We may update this policy if the product’s collection practices change. When we do, we will update the date at the top of this page.
Contact
Privacy questions: privacy@sneebly.app